Courseiva

CCNA Junos OS Fundamentals Questions

59 questions · Junos OS Fundamentals · All types, answers revealed

1
MCQhard

An engineer suspects that a recent software upgrade caused a compatibility issue. Which command should be used to revert the Junos OS to the previous version?

A.rollback 0
B.request system software rollback
C.request system reboot
D.request system software delete jinstall-*.tgz
AnswerB

The 'request system software rollback' command is the correct way to revert a Junos device to the previous operating system version after an upgrade. Junos maintains two software partitions (the current and previous), and this command marks the previous partition as the primary boot image, then reboots the device to activate that older version. This is the intended recovery mechanism when a recent upgrade causes problems.

Why this answer

The 'request system software rollback' command is the correct method to revert the Junos OS to the previously installed version. This command triggers a reboot and loads the previous software set from the /altroot partition, effectively undoing the upgrade while preserving the configuration.

Exam trap

The trap here is confusing 'rollback' in the context of configuration management (rollback 0) with software version rollback, leading candidates to mistakenly choose option A.

How to eliminate wrong answers

Option A is wrong because 'rollback 0' reverts the candidate configuration to the most recently committed configuration, not the operating system software version. Option C is wrong because 'request system reboot' simply reboots the device without changing the software version. Option D is wrong because 'request system software delete' removes a software package from storage but does not activate a previous version; the device would still boot the current version unless a rollback is performed.

2
Multi-Selectmedium

Which THREE actions can be performed in operational mode on a Junos device?

Select 3 answers
A.Commit configuration changes
B.Ping a remote host
C.Configure interface IP addresses
D.View system logs
E.Reboot the chassis
AnswersB, D, E

Pinging a remote host is a standard operational-mode command in Junos, executed as 'ping <address>' from the CLI's operational prompt (user@router>). It sends ICMP echo requests and displays round-trip statistics without changing any system state. Because it performs a connectivity test rather than a configuration change, it is correctly classified as an operational action.

Why this answer

In Junos, operational mode is the CLI mode entered after login (prompt user@host>), used for monitoring and controlling device state. Option B (Ping a remote host) is correct because the ping command is an operational-mode command used to test reachability to a remote host. Option D (View system logs) is correct because operational mode provides commands such as show log messages to inspect system log files.

Option E (Reboot the chassis) is correct because the request system reboot command is executed from operational mode to restart the device. Options A and C are not operational-mode actions: committing configuration changes (commit) and configuring interface IP addresses (set interfaces ...) are performed in configuration mode, which is entered with the configure command.

Exam trap

The trap here is that candidates familiar with Cisco IOS may mistakenly think that configuration commands like 'commit' or 'set interface' can be executed in operational mode, but Junos strictly enforces the separation between operational and configuration modes.

3
MCQeasy

A network administrator needs to remove all configuration changes made since the last commit without affecting the current active configuration. Which command should be used?

A.rollback 1
B.deactivate
C.rollback 0
D.delete
AnswerC

The `rollback 0` command precisely addresses the requirement to discard uncommitted changes. When executed in configuration mode, it reverts the *candidate configuration* to the state of the *last committed configuration*. This action effectively removes all modifications made since the previous commit without impacting the *active configuration* currently running on the device. The active configuration remains unaffected because `rollback 0` operates solely on the pending configuration, ensuring operational stability.

Why this answer

The `rollback 0` command reverts the candidate configuration to the currently active committed configuration, discarding all uncommitted changes without affecting the active configuration. This is the correct way to undo all modifications made since the last commit while keeping the running configuration intact.

Exam trap

The trap here is confusing `rollback 0` with `rollback 1`; candidates often think rollback 1 reverts to the last committed state, but rollback 0 is the correct way to discard uncommitted changes while preserving the active configuration.

How to eliminate wrong answers

Option A is wrong because `rollback 1` reverts to the configuration from the previous commit, not the current active configuration, and would discard the last committed changes. Option B is wrong because `deactivate` only disables a specific configuration statement or hierarchy, it does not remove all uncommitted changes. Option D is wrong because `delete` removes specific configuration statements from the candidate configuration, but it does not revert all uncommitted changes in a single operation.

4
MCQmedium

A network administrator is configuring a new interface and wants to ensure that the interface is enabled and can pass traffic. Which configuration element is required?

A.set interfaces ge-0/0/0 enable
B.set interfaces ge-0/0/0 unit 0 family inet address 192.168.1.1/24
C.set interfaces ge-0/0/0 unit 0 family inet
D.set interfaces ge-0/0/0 disable
AnswerB

This command assigns an IPv4 address to unit 0 on ge-0/0/0, which automatically creates the logical interface and ties the inet address family to it. Once the address is committed, the interface is implicitly enabled and becomes operationally eligible to carry traffic. This is the correct minimal configuration for the task because it provides the required IP details and activates the interface without needing any additional 'enable' statement.

Why this answer

In Junos, an interface is administratively enabled by default (no explicit 'enable' command is needed), but to pass traffic it requires a logical unit with a configured protocol family and an IP address. The command 'set interfaces ge-0/0/0 unit 0 family inet address 192.168.1.1/24' creates unit 0, assigns the IPv4 address, and implicitly enables the interface for traffic forwarding. Without an address under a family, the interface cannot pass IP traffic even if it is administratively up.

Exam trap

The trap here is that candidates familiar with Cisco IOS may expect an explicit 'no shutdown' command (or an 'enable' keyword) to bring an interface up, but Junos interfaces are enabled by default, and the critical missing piece is the IP address under the logical unit, not an administrative enable command.

How to eliminate wrong answers

Option A is wrong because Junos does not have an 'enable' knob at the interface level; interfaces are administratively enabled by default, and the correct way to disable them is with 'disable'. Option C is wrong because 'set interfaces ge-0/0/0 unit 0 family inet' only enables the IPv4 protocol family on the logical unit but does not assign an IP address, so the interface cannot pass traffic (no local route or ARP entry is generated). Option D is wrong because 'set interfaces ge-0/0/0 disable' explicitly disables the interface, preventing it from passing any traffic, which is the opposite of the requirement.

5
MCQhard

A technician notices that the /var partition on a Junos device is 95% full. Which action will immediately free up disk space without affecting device operation?

A.Delete unused software packages using 'request system software delete'
B.Reboot the device
C.Remove the /var/log directory
D.Clear log files using 'clear log messages'
AnswerD

Using 'clear log messages' is the correct immediate action because it truncates the active log files under /var/log (specifically /var/log/messages) and instantly releases all allocated blocks to the filesystem, freeing space in /var without requiring a reboot or commit. The syslog daemon continues writing to the file, which is recreated/truncated gracefully, so no logging interruption or packet loss occurs. This targeted approach addresses the symptom—a full /var partition—while preserving all other system files and services.

Why this answer

The 'clear log messages' command immediately removes the contents of the active log files (e.g., messages, interactive-commands) without requiring a reboot or affecting running processes. This directly frees up space in /var/log, which is a primary consumer of the /var partition, while leaving the directory structure intact so logging continues normally.

Exam trap

The trap here is that candidates may think rebooting (Option B) clears all temporary files and logs, but Junos does not automatically delete persistent log files on reboot; only volatile /tmp is cleared, so /var remains full.

How to eliminate wrong answers

Option A is wrong because 'request system software delete' removes inactive software packages from /var/sw/pkg, but if the /var partition is 95% full due to log files, this action may not free significant space and could be unnecessary; also, it does not immediately address the most common cause of /var fullness. Option B is wrong because rebooting the device does not delete any files; it only clears temporary runtime data in /tmp and /var/tmp, but persistent log files in /var/log remain, so disk space is not freed. Option C is wrong because removing the /var/log directory would break logging functionality, cause loss of forensic data, and potentially disrupt system operations (e.g., syslogd may fail to start), which violates the requirement of not affecting device operation.

6
MCQhard

Refer to the exhibit. An administrator wants to ensure that log messages are stored even if the remote syslog server becomes unavailable. What additional configuration is required?

A.set system syslog archive world-readable
B.set system syslog host 10.10.10.1 facility-override
C.set system syslog rate-limit 1000
D.set system syslog file messages any any
AnswerD

Configuring a local log file with `set system syslog file messages any any` ensures that log messages are stored locally on the device, even if the remote syslog server becomes unavailable. This provides a persistent local copy of logs that can be reviewed later, independent of the remote server's reachability.

Why this answer

Configuring a local log file with `set system syslog file messages any any` ensures that log messages are stored locally on the device, even if the remote syslog server becomes unavailable. This provides a persistent local copy of logs that can be reviewed later, independent of the remote server's reachability.

Exam trap

The trap here is that candidates often confuse remote syslog configuration (host) with local logging (file), assuming that simply configuring a remote server is sufficient for all logging needs, but Junos requires an explicit local file to store logs locally when the remote server is unavailable.

How to eliminate wrong answers

Option A is wrong because `set system syslog archive world-readable` only changes file permissions on archived log files, not the ability to store logs locally when the remote server is down. Option B is wrong because `set system syslog host 10.10.10.1 facility-override` modifies the facility tag of messages sent to the remote server, but does not create any local storage. Option C is wrong because `set system syslog rate-limit 1000` controls the rate at which log messages are generated, not where they are stored, and does not address local logging.

7
MCQmedium

Refer to the exhibit. The network administrator made a change that caused connectivity loss. They need to revert to the configuration before the most recent commit. Which command would accomplish this?

A.rollback 0
B.rollback 3
C.rollback 2
D.rollback 1
AnswerD

rollback 1 loads the configuration that was committed before the most recent commit. Because the administrator's latest change caused the connectivity loss, this returns the network to the exact working state immediately prior to that change. It is the only rollback target that precisely reverts the faulty modification while preserving all earlier configuration data.

Why this answer

In Junos, rollback numbers are stored with 0 being the most recent committed configuration. To revert to the configuration before the most recent commit, you need to load the configuration that was active before that change. That is rollback 1, which represents the second most recent commit.

Using rollback 0 would load the configuration that caused the issue, not fix it.

Exam trap

Many candidates mistakenly believe that rollback 0 undoes the last change. However, rollback 0 loads the most recent committed configuration—the one that caused the connectivity loss—so it would reload the problem, not fix it. To revert to the configuration before the last commit, you must use rollback 1.

How to eliminate wrong answers

Option B (rollback 3) is wrong because rollback 3 refers to the configuration from three commits ago, not the most recent commit. Option C (rollback 2) is wrong because rollback 2 refers to the configuration from two commits ago. Option D (rollback 1) is wrong because rollback 1 refers to the configuration immediately before the last commit, which is the same as the current active configuration after the last commit, not the configuration before the most recent commit.

The key distinction is that rollback 0 is the most recent commit, while rollback 1 is the previous commit.

8
MCQeasy

An engineer notices that a Juniper device is not saving configuration changes across reboots. What is the most likely cause?

A.The rescue configuration is not set.
B.The device is booting from factory-default configuration.
C.The candidate configuration was not committed.
D.The command 'request system reboot' was used instead of 'commit'.
AnswerC

In Junos, configuration changes are held in the candidate configuration until you issue the 'commit' command, which activates and saves them to /config/juniper.conf.gz. Without a commit, the changes exist only in the volatile candidate buffer and are discarded on reboot or when a rollback is performed. Therefore, the most direct explanation for changes not being saved is that the candidate configuration was never committed.

Why this answer

In Junos OS, configuration changes are stored in a candidate configuration and only become active and persistent across reboots after a 'commit' operation. Without a commit, the changes remain in the candidate buffer and are discarded upon reboot, causing the device to revert to the last committed configuration.

Exam trap

The trap here is that candidates familiar with Cisco IOS may assume changes are saved automatically or with a 'copy running-config startup-config' equivalent, but Junos requires an explicit 'commit' to make changes persistent across reboots.

How to eliminate wrong answers

Option A is wrong because the rescue configuration is a separate, manually saved configuration used for recovery; its absence does not prevent normal configuration saves from persisting across reboots. Option B is wrong because booting from factory-default would require a specific action (e.g., 'request system zeroize' or loading factory-default), and the device normally boots from the last committed configuration, not factory-default. Option D is wrong because 'request system reboot' is a command to reboot the device, not a configuration command; it does not replace the need for 'commit' to save changes.

9
MCQmedium

A junior engineer is troubleshooting connectivity issues and wants to trace the path packets take to a remote destination. Which Junos command should be used?

A.monitor traffic
B.show route
C.traceroute
D.ping
AnswerC

traceroute is the correct tool because it actively probes the network path by sending packets with incrementally increasing TTL values, then collects the ICMP TTL-exceeded messages sent back by each router in turn. This reveals the sequence of IP addresses of every hop along the route to the destination, along with round-trip times for each hop, thus mapping the actual forwarding path hop by hop.

Why this answer

The 'traceroute' command in Junos is specifically designed to trace the path packets take to a remote destination by sending UDP probes with increasing TTL values and analyzing ICMP Time Exceeded messages from intermediate routers. This directly addresses the junior engineer's need to map the Layer 3 path and identify where connectivity failures occur.

Exam trap

The trap here is that candidates often confuse 'ping' (which tests reachability) with 'traceroute' (which traces the path), leading them to select Option D when the question explicitly asks for path tracing rather than simple connectivity testing.

How to eliminate wrong answers

Option A is wrong because 'monitor traffic' is used for real-time packet capture and analysis on an interface, not for tracing the path to a remote destination. Option B is wrong because 'show route' displays the routing table entries on the local device, showing how the local router would forward packets, but it does not actively trace the path taken by packets across multiple hops. Option D is wrong because 'ping' tests reachability and measures round-trip time to a destination, but it does not provide hop-by-hop path information or identify intermediate routers.

10
MCQeasy

What is the primary function of the fxp0 interface on a Juniper device?

A.Internal routing
B.Management interface
C.Loopback testing
D.Data plane forwarding
AnswerB

fxp0 is specifically engineered as an out-of-band management interface, providing administrative access to the device via protocols like SSH, SNMP, and syslog. It is isolated from the data plane and much of the control plane, operating in its own management routing instance, so management connectivity remains available even when the network interfaces are down or the device is not forwarding traffic. This separation allows network operators to recover and configure a device remotely during outages, making fxp0 essential for lifecycle management.

Why this answer

The fxp0 interface is a dedicated out-of-band management Ethernet port on Juniper devices, used exclusively for management traffic such as SSH, SNMP, and syslog. It is separate from the data plane and control plane forwarding interfaces, ensuring administrative access remains available even if the routing or forwarding planes are disrupted.

Exam trap

The trap here is confusing fxp0 with loopback (lo0) or internal RE interfaces, leading candidates to incorrectly select internal routing or loopback testing, when in fact fxp0 is solely for out-of-band management.

How to eliminate wrong answers

Option A is wrong because internal routing between REs or between RE and PFE uses the internal fxp1 or fxp2 interfaces, not fxp0. Option C is wrong because loopback testing is performed on the lo0 interface, which provides a stable IP address for the router and is used for protocols like OSPF and BGP, not for management access. Option D is wrong because data plane forwarding is handled by network interfaces (e.g., ge-, xe-, et-) and the Packet Forwarding Engine (PFE), while fxp0 is strictly an out-of-band management interface that does not participate in forwarding transit traffic.

11
Multi-Selecthard

Which THREE commands are valid in Junos operational mode? (Choose three.)

Select 3 answers
A.show interfaces terse
B.set interfaces ge-0/0/0 unit 0 family inet address 10.0.0.1/24
C.commit and-quit
D.ping 10.0.0.1 count 5
E.request system software add /var/tmp/junos-install.tgz
AnswersA, D, E

The 'show interfaces terse' command is a read-only operational mode command that displays a concise summary of all interface statuses, including administrative state, link state, and protocol family addresses. It is valid in operational mode because it is a 'show' command, which is used for monitoring and troubleshooting, not for modifying the device configuration.

Why this answer

Option A, 'show interfaces terse', is valid in Junos operational mode because show commands are operational-mode commands used to display interface status and configuration summaries. Option D, 'ping 10.0.0.1 count 5', is valid in operational mode because ping is an operational-mode diagnostic command, and 'count 5' correctly limits the number of ICMP echo requests. Option E, 'request system software add /var/tmp/junos-install.tgz', is valid in operational mode because request commands are operational-mode commands used to perform system actions such as installing a Junos software package.

Option B, 'set interfaces ge-0/0/0 unit 0 family inet address 10.0.0.1/24', is a configuration-mode command and is not valid in operational mode. Option C, 'commit and-quit', is also a configuration-mode command used to commit candidate configuration changes and exit configuration mode, so it is not valid in operational mode.

Exam trap

The trap here is that candidates familiar with Cisco IOS may mistakenly think 'set' commands are valid in operational mode, or that 'commit and-quit' is a valid shortcut, when in Junos, operational mode only supports 'show', 'ping', 'traceroute', 'request', and other monitoring commands, while configuration changes require explicit entry into configuration mode.

12
Multi-Selectmedium

Which TWO statements are correct regarding the Junos OS configuration hierarchy?

Select 2 answers
A.The 'commit check' command applies the candidate configuration to the active configuration.
B.The 'load replace' command merges a configuration file into the candidate configuration.
C.The 'show | compare' command displays differences between the candidate and active configurations.
D.The 'rollback 0' command reverts the candidate configuration to the previous state.
E.The 'set' command is used to modify the candidate configuration.
AnswersC, E

When you execute 'show | compare' in configuration mode, Junos displays the differences between the candidate configuration and the active configuration, prefixed with '+' for additions and '-' for deletions. This is a read-only diagnostic that helps you review pending changes before committing, and it does not modify either configuration.

Why this answer

Option C is correct because the 'show | compare' command in Junos displays the differences between the candidate configuration and the active (committed) configuration, allowing operators to review pending changes before committing. Option E is correct because the 'set' command is used in configuration mode to modify the candidate configuration, adding or changing statements in the hierarchy. Option A is incorrect because 'commit check' only validates the candidate configuration for syntax and semantic errors without applying it; the 'commit' command applies it to the active configuration.

Option B is incorrect because 'load replace' replaces the entire candidate configuration with the contents of a file, whereas 'load merge' merges a file into the candidate configuration. Option D is incorrect because 'rollback 0' reverts the candidate configuration to the currently active configuration, discarding uncommitted changes; 'rollback 1' reverts to the previous committed configuration.

13
MCQhard

Refer to the exhibit. A security analyst sees repeated login failures from 10.0.0.2 for user1. Which Junos feature can be used to automatically block further login attempts from that IP?

A.Configure SSH to accept only public key authentication for user1.
B.Disable the user1 account.
C.Set the 'session-limit' for user1 to prevent multiple login attempts.
D.Apply a firewall filter to the loopback interface that polices SSH traffic.
AnswerD

Applying a firewall filter to the loopback interface (lo0.0) is the correct way to protect the Routing Engine's own SSH service. A policer attached to the filter term for SSH traffic can rate-limit the number of packets or bytes per burst; once the configured rate is exceeded, the policer drops subsequent packets from that traffic class, which causes TCP retransmissions and effectively stops further login attempts. For a true per-source limit, the policer should be configured with 'prefix-specific' so that a single attacking IP cannot consume the aggregate allowance and deny SSH to all operators.

Why this answer

Applying a firewall filter to the loopback interface (lo0) that polices SSH traffic can automatically block further login attempts from a specific IP address, such as 10.0.0.2. The loopback interface is the termination point for all control-plane traffic on a Junos device, including SSH sessions. By configuring a firewall filter with a policer that limits the rate of SSH packets from a source IP, excessive login failures can trigger the policer to drop subsequent packets, effectively blocking the attacker without manual intervention.

Exam trap

The trap here is that candidates often confuse control-plane policing (applied to lo0) with data-plane firewall filters applied to interfaces like ge-0/0/0, or mistakenly think that session limits or disabling accounts are automated responses to brute-force attacks.

How to eliminate wrong answers

Option A is wrong because configuring SSH to accept only public key authentication for user1 does not automatically block repeated login failures from 10.0.0.2; it only changes the authentication method, and failed public key attempts could still occur. Option B is wrong because disabling the user1 account is a manual, static action that does not automatically respond to repeated login failures from a specific IP; it also prevents legitimate access for that user. Option C is wrong because the 'session-limit' for user1 limits the number of concurrent sessions, not the rate of login attempts; it does not block repeated failed logins from a single IP address.

14
MCQeasy

A junior network administrator is setting up a Juniper MX router for the first time. After powering on the device, the administrator notices that the LED on the front panel blinks amber and the device does not complete the boot process. The console displays messages reporting file system errors. The administrator has no previous configuration changes and the device was shipped with factory defaults. Which action should the administrator take to resolve the boot issue?

A.Boot into single-user mode and run file system checks.
B.Perform a password recovery procedure to gain access.
C.Use the 'request system software add' command from the boot loader.
D.Reinstall the Junos OS using a USB flash drive with the software image.
AnswerA

Entering single-user mode (e.g., by interrupting the boot process at the U-Boot loader and issuing `boot -s`) provides a maintenance shell before normal Junos processes start. From there, you can manually run filesystem consistency checks with `fsck` (or `check`) on the root and /var partitions. Repairing corrupted metadata in this mode is the standard first-line recovery step for a device that fails to boot cleanly, as it addresses the underlying filesystem errors without the risk of an immediate full reinstall.

Why this answer

The amber blinking LED and file system errors indicate a corrupted file system, which is common on factory-default devices if the flash memory was not properly initialized. Booting into single-user mode (option A) allows the administrator to run 'fsck' (file system check) to repair the root file system without loading the full Junos OS, which is the standard recovery procedure for such boot failures.

Exam trap

The trap here is that candidates may confuse a boot failure due to file system corruption with a password issue or a need to reinstall the OS, but the amber LED and file system error messages point directly to a corrupted file system that can be repaired with fsck in single-user mode.

How to eliminate wrong answers

Option B is wrong because password recovery is used to reset login credentials, not to repair file system corruption; the device cannot boot, so password recovery is irrelevant. Option C is wrong because 'request system software add' is a Junos CLI command that requires a fully booted system, not the boot loader; the boot loader does not support this command. Option D is wrong because reinstalling Junos OS from a USB is a more drastic step that should only be taken if file system checks fail; it is not the first-line action for file system errors on a factory-default device.

15
Multi-Selecthard

Which TWO commands are used to install and remove software packages on a Junos device?

Select 2 answers
A.request system software delete
B.request system software rollback
C.show system software
D.request system reboot
E.request system software add
AnswersA, E

request system software delete: This command removes an installed software package from the storage of the Junos device. It is used to free up disk space or to remove an old package prior to an upgrade, and it does not affect the currently running version until a reboot activates a change. The package name must be specified, and the operation is persistent across reboots once committed.

Why this answer

Option A, `request system software delete`, is correct because it is the Junos operational-mode command used to remove an installed software package (such as a Junos image or an individual package) from the device. Option E, `request system software add`, is correct because it is the Junos command used to install a new software package or Junos image onto the device, typically referencing a local file or URL. Option B, `request system software rollback`, is incorrect because it reverts the system to a previously installed software version rather than installing or removing a package.

Option C, `show system software`, is incorrect because it only displays information about installed software and does not modify it. Option D, `request system reboot`, is incorrect because it restarts the device and does not install or remove any software package.

Exam trap

The trap here is that candidates confuse `request system software rollback` with a removal command, but it actually reverts to a previous version without deleting the current package from the system.

16
MCQmedium

A network administrator makes several changes to the configuration but decides to discard all uncommitted changes and start fresh. Which command should be used to revert the candidate configuration back to the current active configuration?

A.load override
B.rollback 0
C.commit check
D.rollback 1
AnswerB

rollback 0 discards all uncommitted changes and reloads the candidate configuration to exactly match the current committed (active) configuration. The index 0 always points to the most recent commit, so this operation cleans the candidate without altering the running configuration. Since the administrator simply wants to start fresh from the last committed state, rollback 0 is the precise command. Note that you still must issue a commit to make any further changes active, but no commit is required to just discard edits.

Why this answer

The 'rollback 0' command reverts the candidate configuration to the currently active configuration, discarding all uncommitted changes. This is because Junos maintains a rollback database of the last 50 committed configurations, with index 0 always representing the active configuration. Using 'rollback 0' effectively resets the candidate configuration to match the active one, allowing the administrator to start fresh without affecting the running system.

Exam trap

The trap here is that candidates often confuse 'rollback 0' with 'rollback 1', mistakenly thinking that 'rollback 1' discards uncommitted changes, when in fact 'rollback 1' reverts to the previous committed configuration, which would undo the last commit and potentially cause service disruption.

How to eliminate wrong answers

Option A is wrong because 'load override' replaces the entire candidate configuration with the contents of a specified file, not with the current active configuration; it does not discard uncommitted changes by reverting to the active config. Option C is wrong because 'commit check' validates the syntax and semantics of the candidate configuration without committing it, and does not discard any changes. Option D is wrong because 'rollback 1' reverts to the previous committed configuration (the one before the most recent commit), not to the current active configuration; this would discard the last committed changes, not just uncommitted ones.

17
MCQmedium

You are a network engineer at a company that operates a pair of Juniper SRX firewalls in an active/passive cluster (Chassis Cluster). The cluster has been running Junos 15.1X49-D100 for over a year. Management has mandated an upgrade to a newer version to address security vulnerabilities. You follow the recommended upgrade procedure and successfully upgrade the primary node (node0) first, then failover to make node0 the backup, and upgrade the new primary (node1). After the upgrade, both nodes have the same version and appear to be in the cluster, but you notice that the backup node (node0) is stuck in 'ineligible' state and does not synchronize configuration changes. What is the most likely cause?

A.The cluster control link is down or misconfigured on the backup node
B.The backup node has not been configured with 'commit synchronize'
C.The 'set chassis cluster reth-count' statement is missing on the backup node
D.The 'monitor interface' configuration is causing a mis-match between nodes
AnswerA

A node becomes ineligible when the cluster control link is not operational on that node, because the control link is the physical interface used to exchange heartbeat messages and cluster control traffic. If the control link is down, misconfigured (e.g., wrong interface name, VLAN mismatch, or disabled), or not connected, the node cannot participate in cluster state synchronization or failover, forcing it into the ineligible state. Even if the node is otherwise healthy and has all other cluster settings correct, the lack of a functioning control link alone is sufficient to prevent it from reaching eligible status.

Why this answer

The backup node being stuck in 'ineligible' state after a chassis cluster upgrade indicates that the cluster control link (control port) is not functioning correctly. In a Juniper SRX active/passive cluster, the control link is used for heartbeat and cluster state synchronization; if it is down or misconfigured on the backup node, the node cannot participate in the cluster election process and remains ineligible. This is a common issue after upgrades if the control link interfaces are not properly re-established or if the cable is faulty.

Exam trap

The trap here is that candidates often confuse 'ineligible' state with configuration synchronization issues, leading them to choose 'commit synchronize' or other configuration-related options, when the root cause is actually a physical or logical connectivity problem on the control link.

How to eliminate wrong answers

Option B is wrong because 'commit synchronize' is a configuration command that ensures changes are automatically synchronized from the primary to the backup node, but it does not affect the node's eligibility state; the backup node can still be eligible without it. Option C is wrong because the 'set chassis cluster reth-count' statement defines the number of redundant Ethernet interfaces and is required for cluster operation, but its absence would cause a different issue (e.g., reth interfaces not working), not specifically the backup node being stuck in 'ineligible' state. Option D is wrong because 'monitor interface' configuration is used for interface monitoring to trigger failover, and a mismatch between nodes would cause a different problem (e.g., false failovers), not the backup node being stuck in 'ineligible' state.

18
MCQmedium

An engineer wants to roll back to the previous configuration. Which command should be used?

A.rollback 1
B.delete
C.rollback 0
D.commit check
AnswerA

The `rollback 1` command reloads the candidate configuration from the previous committed configuration (rollback ID 1), completely discarding any uncommitted changes currently staged in the candidate. This precisely achieves the engineer's goal of returning to the previous configuration, making it the correct command for this scenario.

Why this answer

The `rollback 1` command loads the previous committed configuration (the configuration before the last commit) into the candidate configuration, discarding any uncommitted changes. This allows the engineer to replace the current candidate with the desired historical configuration. In Junos, `rollback 0` loads the most recently committed configuration (the current active configuration), not the previous one.

Exam trap

Candidates often think that `rollback 0` is the previous configuration, but `rollback 0` actually loads the currently active configuration. `rollback 1` is the previous committed configuration.

How to eliminate wrong answers

Option B is wrong because `delete` removes configuration statements from the candidate configuration, not from the committed configuration, and it does not perform a rollback to a previous state. Option C is wrong because `rollback 0` reverts the candidate configuration to the currently active committed configuration, which would discard any uncommitted changes the engineer wants to keep. Option D is wrong because `commit check` only validates the syntax and semantics of the candidate configuration without committing it; it does not roll back to any previous configuration.

19
MCQeasy

An engineer wants to view the current active configuration file that the device is using. Which command displays this information?

A.show configuration candidates
B.show system commit
C.show configuration
D.show configuration | display set
AnswerC

This displays the active committed configuration.

Why this answer

The 'show configuration' command displays the current active configuration that the device is using, which is the committed configuration stored in /config/juniper.conf.gz. This command reads the active configuration file directly from the file system, showing the exact operational configuration that Junos applies to the device.

Exam trap

The trap here is that candidates may confuse 'show configuration' with 'show configuration | display set' or think 'show system commit' shows the active config, when in fact it only shows commit history, not the current running configuration.

How to eliminate wrong answers

Option A is wrong because 'show configuration candidates' is not a valid Junos command; the correct command to view candidate configuration is 'show configuration' without any modifier, or 'show | compare' to see changes. Option B is wrong because 'show system commit' displays the commit history log, including timestamps and user information, not the active configuration file itself. Option D is wrong because 'show configuration | display set' is a pipe modifier that reformats the output into set commands, but it still shows the active configuration; however, the question asks for the command that displays the active configuration file, and the base command is 'show configuration', not the piped variant.

20
MCQeasy

An engineer needs to view the current active configuration on a Juniper device. Which command will display the configuration that is currently running?

A.show chassis hardware
B.show interfaces terse
C.show configuration
D.show system commit
AnswerC

`show configuration` is the correct Junos command to view the active configuration. In operational mode, it displays the candidate configuration, which reflects the currently committed active configuration plus any uncommitted changes; if no edits are pending, it shows the committed configuration verbatim. The command outputs the entire configuration hierarchy from the top level and can be filtered or scoped to a specific hierarchy, making it the definitive way to inspect the device's active or candidate configuration.

Why this answer

The 'show configuration' command displays the current active configuration that is committed and running on a Juniper device. Unlike Cisco's 'show running-config', Junos uses a commit model where the candidate configuration is activated only after a 'commit' operation, and 'show configuration' shows that committed, active configuration.

Exam trap

Juniper Networks often tests the 'show running-config' equivalent, and the trap here is that candidates familiar with Cisco may mistakenly choose 'show system commit' (thinking it shows the running config) or 'show interfaces terse' (confusing interface status with the full configuration).

How to eliminate wrong answers

Option A is wrong because 'show chassis hardware' displays physical hardware inventory details (e.g., serial numbers, part numbers, firmware versions), not the running configuration. Option B is wrong because 'show interfaces terse' shows a summary of interface status and configuration (like IP addresses and administrative state), but not the full active configuration. Option D is wrong because 'show system commit' lists the commit history (timestamps, log messages, and rollback IDs), not the current running configuration.

21
Multi-Selectmedium

Which TWO statements are true regarding Junos configuration groups?

Select 2 answers
A.Configuration groups never override existing settings.
B.Configuration groups are applied using the apply-groups statement.
C.Configuration groups are only useful for interface configuration.
D.Configuration groups are applied automatically to all hierarchies.
E.Configuration groups are applied in the order they are listed in apply-groups.
AnswersB, E

This is a true statement. In Junos, configuration groups are defined under the `groups` hierarchy, and to activate them, you must reference them via the `apply-groups` statement at the appropriate hierarchy level. For example, applying `apply-groups global` at the top-level ensures that the settings from the `global` group are merged into the active configuration. Without an explicit `apply-groups` statement, a configuration group has no effect on the running configuration.

Why this answer

Option B is correct because configuration groups in Junos are explicitly attached to the configuration hierarchy using the apply-groups statement (for example, set interfaces ge-0/0/0 apply-groups GROUP-NAME), which is the mechanism that injects the group's statements into the active configuration. Option E is correct because when multiple groups are referenced in an apply-groups statement, Junos processes them in the order listed, with later groups taking precedence over earlier ones, and the explicit configuration taking precedence over all applied groups. Option A is wrong because group settings can override existing settings depending on inheritance and precedence rules.

Option C is wrong because configuration groups can contain almost any configuration stanza, not just interfaces. Option D is wrong because groups are not applied automatically to all hierarchies; they must be explicitly referenced with apply-groups at the desired hierarchy level.

Exam trap

The trap here is that candidates often assume configuration groups automatically apply to all hierarchies or that they cannot override existing settings, but in reality, groups are explicitly applied and follow a strict precedence order where later groups can override earlier ones.

22
MCQmedium

An engineer needs to copy a configuration from one device to another. Which command should be used to export the current active configuration in a mergeable format?

A.show configuration | display inheritance
B.show configuration | display json
C.show configuration | display set
D.show configuration | save /var/tmp/config.txt
AnswerC

The 'display set' option outputs every configuration statement as a standalone 'set' command, representing the absolute path to each leaf value. This format is the native interchange language for Junos configuration and can be directly merged with 'load merge' or used to compare configurations. It is the recommended way to copy configuration snippets between devices because it is unambiguous and portable.

Why this answer

The 'show configuration | display set' command outputs the current active configuration as a series of 'set' commands, which can be directly copied and applied to another Junos device using 'load set terminal' or 'load merge'. This format is specifically designed for merging configurations, as it represents the configuration in a flat, non-hierarchical structure that Junos can parse incrementally.

Exam trap

The trap here is that candidates often confuse 'display set' with 'display inheritance' or 'display json', thinking any output format can be used for merging, but only 'display set' produces a flat, mergeable command sequence that Junos can load directly.

How to eliminate wrong answers

Option A is wrong because 'show configuration | display inheritance' shows inherited configuration values (e.g., from groups or interfaces) but does not output the configuration in a mergeable format; it is used for troubleshooting inheritance, not for exporting configurations. Option B is wrong because 'show configuration | display json' outputs the configuration in JSON format, which is human-readable and useful for automation but is not directly mergeable into Junos via the CLI; Junos does not support loading JSON configuration directly. Option D is wrong because 'show configuration | save /var/tmp/config.txt' saves the configuration in the default hierarchical (set or curly-brace) format to a file, but the output is not inherently in a mergeable 'set' format unless combined with 'display set'; the 'save' command alone does not transform the output.

23
MCQeasy

Which Junos CLI mode allows a user to view the configuration and execute operational commands, but not make configuration changes?

A.Operational mode
B.Monitor mode
C.Enable mode
D.Configuration mode
AnswerA

Operational mode, indicated by the `>` prompt, is the default Junos CLI mode. It allows users to run `show` commands, including `show configuration` and its variants, to view the active configuration without making any changes. This mode is sufficient for viewing; entering configuration mode is unnecessary for read-only access.

Why this answer

In Junos OS, Operational mode (indicated by the `>` prompt) allows users to execute operational commands (e.g., `show`, `ping`, `traceroute`) and view the active configuration using `show configuration`, but it does not permit any changes to the configuration. Configuration changes require entering Configuration mode (indicated by the `#` prompt) via the `configure` command. This separation enforces a strict two-tier access model, ensuring that operational tasks do not inadvertently alter the device's configuration.

Exam trap

The trap here is that candidates familiar with Cisco IOS may confuse 'Enable mode' (which grants configuration privileges in Cisco) with Junos's Operational mode, not realizing that Junos uses a completely different two-tier model where Operational mode is read-only and Configuration mode is required for any changes.

How to eliminate wrong answers

Option B (Monitor mode) is wrong because Junos does not have a 'Monitor mode'; this term is a distractor that might be confused with Cisco's monitor mode for software upgrades or with the `monitor` operational command used for real-time interface traffic viewing. Option C (Enable mode) is wrong because 'Enable mode' is a Cisco IOS concept that provides privileged access for configuration changes; Junos uses a different paradigm with distinct Operational and Configuration modes. Option D (Configuration mode) is wrong because this mode (indicated by the `#` prompt) is specifically designed for making configuration changes, not for viewing the configuration or executing operational commands without the ability to modify settings.

24
MCQmedium

A technician is troubleshooting a device that has an inconsistent configuration. They need to revert to the configuration that was committed exactly two commits ago. Which command sequence accomplishes this?

A.rollback 2
B.rollback 2 followed by commit
C.commit confirmed 2
D.rollback 3
AnswerB

rollback 2 followed by commit is the correct two-step procedure: rollback 2 loads the candidate configuration from the second previous commit (index 2), discarding any uncommitted changes, and commit then activates that candidate as the new active configuration. This fully reverts the device to the exact state it had two commits earlier, which is what the technician needs. Remember that rollback alone only stages the changes; only a commit applies them.

Why this answer

The `rollback 2` command reverts the candidate configuration to the state it was in two commits ago, but the change is not applied until a `commit` is issued. This two-step sequence (rollback followed by commit) is required to make the reverted configuration active. Without the commit, the device continues running the current active configuration.

Exam trap

The trap here is that candidates often assume `rollback 2` alone immediately reverts the active configuration, forgetting that Junos requires an explicit `commit` to apply candidate changes.

How to eliminate wrong answers

Option A is wrong because `rollback 2` alone only loads the configuration from two commits ago into the candidate configuration; it does not commit it, so the device continues to operate with the current active configuration. Option C is wrong because `commit confirmed 2` is used to automatically roll back after 2 minutes if not confirmed, not to revert to a configuration from two commits ago. Option D is wrong because `rollback 3` reverts to the configuration from three commits ago, not two commits ago.

25
MCQeasy

Which command saves the current operational state information to a file that can be provided to Juniper support for troubleshooting?

A.request support information
B.monitor traffic
C.show system information
D.file copy
AnswerA

request support information invokes a Junos operational-mode script that bundles the configuration, routing tables, interface statistics, logs, and core dumps into a timestamped archive (e.g., juniper.support.tgz) under /var/tmp. It is the automated equivalent of a full 'tech-support' bundle for JTAC analysis and is the only option here that automatically captures and persists operational state to a file.

Why this answer

The 'request support information' command collects a comprehensive snapshot of the current operational state, including configuration, logs, routing tables, and interface statistics, and packages it into a file (e.g., /var/tmp/support-info-date-time.tgz) that can be directly provided to Juniper support for troubleshooting. This is the standard Junos method for gathering diagnostic data.

Exam trap

The trap here is that candidates may confuse 'show system information' with a support data collection tool, not realizing it only displays a brief summary and does not generate a comprehensive, saveable file for support.

How to eliminate wrong answers

Option B is wrong because 'monitor traffic' is used for real-time packet capture and display, not for saving a static snapshot of operational state to a file. Option C is wrong because 'show system information' displays basic system details like uptime and model but does not save the output to a file or collect the comprehensive data set needed for support. Option D is wrong because 'file copy' is a generic command for copying files between locations and does not generate or collect operational state information.

26
MCQhard

During a network traffic storm, a Juniper EX switch's CPU utilization spikes to 100%. Which command would best help identify the cause?

A.monitor traffic interface ge-0/0/0
B.show spanning-tree bridge
C.show ethernet-switching table
D.show interfaces extensive ge-0/0/0
AnswerA

`monitor traffic interface ge-0/0/0` runs a real-time packet capture on the specified interface, displaying packet headers so you can see broadcast, multicast, or unknown-unicast traffic flooding the switch. This is the key diagnostic during a storm because it lets you identify the source MAC/IP and the packet type that is overwhelming the CPU. It captures traffic as it arrives, giving immediate evidence for where the storm originates.

Why this answer

The 'monitor traffic interface' command captures live packet headers on the specified interface, allowing you to see the type and source of traffic causing the CPU spike. During a traffic storm (e.g., broadcast storm), this command reveals excessive broadcast, multicast, or unknown unicast frames, which are typically the root cause of high CPU utilization on Juniper EX switches.

Exam trap

The trap here is that candidates often confuse 'show interfaces extensive' (which shows error counters like CRC errors or giants) with the ability to see live traffic, but it only provides historical statistics, not the packet-level detail needed to pinpoint the storm's source.

How to eliminate wrong answers

Option B is wrong because 'show spanning-tree bridge' displays STP bridge parameters and port roles, which help diagnose Layer 2 loops but not the specific traffic types or sources causing a CPU storm. Option C is wrong because 'show ethernet-switching table' shows MAC address entries and their associated interfaces, which is useful for verifying forwarding tables but does not reveal real-time traffic patterns or packet contents. Option D is wrong because 'show interfaces extensive' provides detailed interface statistics and errors, but it does not capture live packet data; it only shows counters and historical data, not the actual traffic causing the CPU spike.

27
MCQeasy

An administrator needs to quickly revert all uncommitted configuration changes and return the device to the last committed configuration. Which command accomplishes this?

A.rollback 0
B.delete configuration
C.load override
D.rollback 1
AnswerA

The correct way to quickly discard all uncommitted changes in the candidate configuration is to execute 'rollback 0' in configuration mode. This operation overwrites the candidate configuration with the contents of the most recent committed configuration, effectively resetting any modifications made since the last commit. It is the fastest method because it does not require a reboot or additional file operations, and you can verify the change by entering 'show configuration' to confirm the candidate now matches the active configuration.

Why this answer

The command 'rollback 0' reverts all uncommitted configuration changes and returns the device to the last committed configuration. In Junos, the rollback command uses a numeric argument to specify which previous configuration to load, with 0 always referring to the most recently committed configuration. This effectively discards any pending changes in the candidate configuration without requiring a commit.

Exam trap

The trap here is that candidates often confuse 'rollback 0' with 'rollback 1', mistakenly thinking rollback 1 reverts to the last committed configuration, when in fact rollback 0 is the correct index for the most recent commit, and rollback 1 refers to the configuration before that.

How to eliminate wrong answers

Option B is wrong because 'delete configuration' is not a valid Junos command; the correct approach to remove all configuration is to use 'delete' within configuration mode on specific hierarchies or use 'load override terminal' with an empty configuration, not a single command. Option C is wrong because 'load override' replaces the entire candidate configuration with a specified file or terminal input, but it does not automatically revert to the last committed configuration; it requires an explicit source (e.g., a file) and does not default to rollback 0. Option D is wrong because 'rollback 1' reverts to the configuration that was committed before the most recent commit (i.e., the previous committed configuration), not the last committed one, so it would not discard uncommitted changes if the candidate has not been committed.

28
MCQeasy

A company wants to implement best practice for password recovery on Juniper devices to avoid service disruption. Which of the following is the recommended method?

A.Perform a factory reset to default configuration
B.Boot the device into single-user mode from the console and reset the root password
C.Use SNMP to modify the password field in the configuration
D.Contact JTAC to remotely reset the password
AnswerB

Booting into single-user mode from the console grants root shell access without loading the full configuration, allowing the root password to be reset without wiping the device. This preserves existing configuration and avoids the service disruption that a factory reset would cause.

Why this answer

Booting the device into single-user mode from the console is the standard, secure method for password recovery on Juniper devices. This process allows an administrator with physical console access to reset the root password without affecting the running configuration or causing service disruption, as the device boots with a minimal kernel and does not load the full configuration.

Exam trap

The trap here is that candidates may confuse Juniper's single-user mode recovery with Cisco's password recovery process, which often involves a configuration register change and may require a factory reset; Juniper's method is designed to preserve the configuration, while Cisco's recovery can sometimes erase the startup configuration if not done carefully.

How to eliminate wrong answers

Option A is wrong because performing a factory reset to default configuration erases all configuration data, causing complete service disruption and loss of custom settings, which is not a best practice for password recovery. Option C is wrong because SNMP is a monitoring and management protocol that does not provide a mechanism to modify password fields in the Junos configuration; it is read-only for security purposes and cannot be used for password changes. Option D is wrong because contacting JTAC to remotely reset the password is not a standard or recommended procedure; JTAC does not have direct access to reset passwords, and this would require a support contract and potentially cause delays, not to mention that remote password reset is not a supported feature.

29
MCQmedium

Refer to the exhibit. Which log file will contain messages about authorization events?

A.messages
B.Both messages and interactive-commands
C.Neither
D.interactive-commands
AnswerA

The `file messages` syslog configuration in the exhibit contains an explicit `authorization info` statement, which tells the Junos syslog daemon to capture authorization events at priority `info` and above. Because the event shown is an authorization event, it matches this filter and is written to `/var/log/messages`. No other file in the exhibit has an authorization filter, so `messages` is the correct destination.

Why this answer

In Junos, the 'messages' log file (typically /var/log/messages) records system log messages, including authorization events such as user login failures, privilege escalation attempts, and configuration changes. Authorization events are generated by the system's authentication, authorization, and accounting (AAA) framework and are logged at the 'info' severity level by default, which is captured in the messages file. The 'interactive-commands' log file specifically records CLI commands entered by users, not authorization events.

Exam trap

The trap here is that candidates confuse 'interactive-commands' (which logs CLI commands) with authorization logging, assuming that because commands require authorization, the log file would contain authorization events, but Junos separates command logging from authorization event logging.

How to eliminate wrong answers

Option B is wrong because 'interactive-commands' logs only the actual CLI commands typed by users, not authorization events; authorization events are separate and appear in 'messages'. Option C is wrong because authorization events are indeed logged in Junos, specifically in the 'messages' file, so 'Neither' is incorrect. Option D is wrong because 'interactive-commands' does not contain authorization messages; it is dedicated to recording user-entered commands for auditing purposes.

30
MCQhard

Refer to the exhibit. An administrator notices repeated failed login attempts. What should be configured to mitigate this attack?

A.Set login retry limit
B.Configure a firewall filter to block the source IP
C.Disable SSH
D.Change the root password
AnswerB

Creating a firewall filter that discards (or rejects) traffic from the offending source IP at the interface or loopback level causes Junos to drop those packets before they reach the SSH or login process. This stops the brute-force traffic immediately at Layer 3/4, preserving the SSH service for legitimate sources. On Junos, applying an input filter to the loopback interface (lo0) is a common method to filter management-plane traffic, which directly halts further attempts from that specific IP.

Why this answer

A firewall filter can block traffic from the source IP address of the repeated failed login attempts, preventing further access from that host. This is a direct and immediate mitigation against an ongoing brute-force attack, as it stops the attacker's traffic at the network layer before it reaches the SSH or login service.

Exam trap

The trap here is that candidates often confuse mitigation (stopping an ongoing attack) with prevention (hardening against future attacks), leading them to choose retry limits or password changes instead of the immediate IP-blocking solution.

How to eliminate wrong answers

Option A is wrong because setting a login retry limit only restricts the number of failed attempts per session, but it does not block the source IP; an attacker can simply open new sessions and continue. Option C is wrong because disabling SSH would prevent all remote access, including legitimate administrative access, which is an overly drastic and unnecessary measure. Option D is wrong because changing the root password does not stop the attacker from continuing to try new passwords; it only invalidates the current password, but the attack persists.

31
Multi-Selecthard

Which THREE statements are true about commit operations in Junos OS?

Select 3 answers
A.The 'commit confirmed' command immediately discards changes if not confirmed.
B.Multiple users can make configuration changes simultaneously, but only one can commit at a time.
C.The 'commit check' command validates the configuration syntax without activating it.
D.The 'commit confirmed' command allows a rollback to the previous configuration if not confirmed within the timeout period.
E.The 'commit' command always requires 'commit synchronize' when using dual Routing Engines.
AnswersB, C, D

Junos uses a shared candidate configuration, so several users may edit concurrently, but the commit operation itself is serialised: the commit lock permits only one user to activate changes at any moment, preventing conflicting commits.

Why this answer

Option B is correct because Junos OS uses a shared candidate configuration with per-user edit sessions, so multiple users can edit concurrently, but the commit operation itself is serialized through a lock so only one commit can activate changes at a time. Option C is correct because 'commit check' performs syntax and semantic validation of the candidate configuration against the schema without activating it, leaving the active configuration unchanged. Option D is correct because 'commit confirmed' activates the candidate configuration but automatically rolls back to the previously committed configuration unless the commit is confirmed within the timeout period (default 10 minutes).

Option A is not correct because 'commit confirmed' does not immediately discard changes; it applies them and only rolls back if confirmation is not received before the timer expires. Option E is not correct because 'commit synchronize' is only needed to propagate a commit to both Routing Engines on a dual-RE system, and a plain 'commit' can still be used (it just commits to the local RE unless synchronize is specified).

Exam trap

The trap here is confusing 'commit confirmed' with an immediate discard of changes, when in fact it temporarily activates the configuration and only rolls back if the confirmation is not received within the timeout period.

32
Multi-Selecteasy

Which TWO statements about the Junos OS configuration hierarchy are correct? (Choose two.)

Select 2 answers
A.All configuration is stored in a flat file with line numbers
B.The hierarchy is stored in multiple configuration files that are merged at boot
C.Configuration is organized in a hierarchical structure with levels
D.Configuration values are inherited from the root level automatically
E.Each level can contain one or more statements or values
AnswersC, E

Junos uses a tree-like hierarchy where configuration statements are nested under levels, such as protocols>bgp>group>neighbor. Each level is defined by the statement type and indentation in the CLI, allowing modular and structured configuration. This hierarchy is the foundation for editing, viewing, and applying configuration.

Why this answer

Option C is correct because Junos OS stores its configuration in a hierarchical tree structure organized into levels (such as system, interfaces, protocols), which is the defining characteristic of the Junos configuration model. Option E is correct because within that hierarchy, each level can hold one or more statements or values, allowing multiple configuration elements to be nested under a given hierarchy node. Option A is incorrect because Junos does not store configuration as a flat file with line numbers; that describes a line-oriented format, not the Junos hierarchy.

Option B is incorrect because the Junos configuration is not assembled by merging multiple configuration files at boot; it is maintained as a single hierarchical candidate/active configuration. Option D is incorrect because inheritance in Junos flows from parent levels down to child levels, not automatically from the root level to all statements.

Exam trap

The trap here is that candidates often confuse Junos's hierarchical structure with Cisco IOS's flat or modular configuration approach, leading them to incorrectly assume that Junos uses multiple merged files or automatic root-level inheritance.

33
MCQhard

During a maintenance window, an engineer needs to apply a series of configuration changes that are stored in a text file. Which command sequence should be used to load and apply the changes from the file?

A.request system configuration rescue save
B.load override /var/tmp/changes.txt; commit
C.configure; load patch /var/tmp/changes.txt; commit
D.configure; load merge /var/tmp/changes.txt; commit
AnswerD

This sequence correctly applies the configuration changes by merging the contents of changes.txt into the current candidate configuration. The load merge command overlays the file's statements onto the existing configuration, adding new statements and updating existing ones while leaving all unrelated configuration untouched. The commit then activates the candidate configuration, making the changes effective. This is the safest and most precise way to apply an incremental change during a maintenance window, as it avoids deleting any existing configuration.

Why this answer

The engineer needs to enter configuration mode (configure) and then use the 'load merge' command to merge the contents of the text file into the candidate configuration without replacing the entire configuration. The 'commit' command then activates the changes. This is the standard Junos workflow for applying incremental changes from a file.

Exam trap

The trap here is that candidates often confuse 'load merge' with 'load override' or 'load patch', not realizing that 'load merge' is the correct command for applying incremental changes from a standard configuration text file, while 'load override' wipes the entire configuration and 'load patch' requires a specific diff format.

How to eliminate wrong answers

Option A is wrong because 'request system configuration rescue save' saves the current active configuration as a rescue configuration, not loads changes from a file. Option B is wrong because 'load override' replaces the entire candidate configuration with the contents of the file, which would discard all existing configuration not in the file, and the command sequence does not include entering configuration mode ('configure'). Option C is wrong because 'load patch' is used to apply a patch file (a diff between two configurations), not a standard text file of configuration changes; it would likely fail or produce unintended results if the file is not in patch format.

34
MCQhard

Based on the exhibit, what is the most likely impact on the router?

A.Routing protocol adjacencies will be lost, causing routing instability.
B.The CPU will be overloaded due to the kernel messages.
C.The router will stop forwarding packets immediately.
D.The router will reboot automatically.
AnswerA

The rpd (Routing Protocol Daemon) is the sole software process managing all dynamic routing protocols, including OSPF, BGP, and IS-IS. When it is killed, every established adjacency immediately tears down, causing neighboring routers to mark the node unreachable and recalculate paths. This produces route flap and forwarding loops until rpd restarts and rebuilds sessions, so the primary impact is severe routing instability.

Why this answer

The exhibit shows kernel messages indicating a hardware or software fault (e.g., a FPC crash or PIC restart). In Junos, such critical events cause the Packet Forwarding Engine (PFE) to reset, which tears down all routing protocol adjacencies (OSPF, BGP, IS-IS) because the control plane loses communication with the forwarding plane. This leads to route withdrawal and routing instability until the adjacencies are re-established.

Exam trap

The trap here is that candidates assume kernel messages always cause a full reboot or immediate forwarding stop, but Junos is designed to isolate failures to specific components (like FPCs) rather than crashing the entire router.

How to eliminate wrong answers

Option B is wrong because kernel messages are logged as part of normal fault handling and do not inherently overload the CPU; Junos prioritizes control plane stability. Option C is wrong because the router continues to forward packets using the last known forwarding table until the PFE restarts, and even then, forwarding may resume after the restart without a full stop. Option D is wrong because Junos does not automatically reboot on kernel messages; it isolates the faulty component (e.g., FPC restart) to maintain overall system availability.

35
MCQhard

An administrator notices that after committing a configuration change on a Juniper MX router, the device loses connectivity to the management network. The management interface is part of a dedicated management routing instance. Which of the following is the most likely cause?

A.A firewall filter was applied to the management interface that blocks all traffic
B.NTP was configured with an incorrect server address
C.A syslog server was configured that is unreachable
D.The routing instance for the management interface was accidentally removed
AnswerD

The management interface (e.g., fxp0 or me0) is bound to a dedicated routing instance, often named mgmt_junos, which contains the management subnet's route. Removing this routing instance from the configuration causes the interface to lose its association with the routing table, effectively eliminating the route to the management network. As a result, remote management traffic cannot be routed to or from the device, even though the interface itself may still be administratively and operationally up. This correctly explains why the administrator loses connectivity after committing the configuration.

Why this answer

The management interface is part of a dedicated management routing instance (often named mgmt_junos). If this routing instance is accidentally removed during a commit, the management interface loses its routing context and becomes unreachable, causing loss of connectivity to the management network. This is a common misconfiguration when an administrator modifies routing instance configurations without realizing the management interface depends on it.

Exam trap

The trap here is that candidates often assume a firewall filter or service configuration (like NTP or syslog) is the cause, but the real issue is the removal of the routing instance that provides the logical separation for the management interface.

How to eliminate wrong answers

Option A is wrong because applying a firewall filter that blocks all traffic to the management interface would cause immediate loss of connectivity, but the question states the issue occurs after committing a configuration change, and the most likely cause is a structural change to the routing instance rather than a filter. Option B is wrong because configuring NTP with an incorrect server address would not cause loss of management connectivity; it would only prevent time synchronization. Option C is wrong because configuring an unreachable syslog server would only affect logging, not the management interface's ability to communicate on the network.

36
MCQmedium

Based on the exhibit, what is the most likely reason for the ping failure?

A.A firewall filter is blocking ICMP traffic.
B.The interface is disabled at the unit level.
C.The neighbor device is not configured or is unreachable.
D.The interface is administratively down.
AnswerC

The interface status is up/up, meaning the physical link has carrier and the logical unit is active, but this does not guarantee the remote host at 10.0.0.2 is reachable. The ping fails because either the neighbor device is not configured with that IP address, is powered off, or there is no route in the routing table to reach it. A successful ping requires an active ARP entry or a valid route, not just a local interface that is administratively up.

Why this answer

The ping failure is most likely due to the neighbor device not being configured or unreachable because the output shows the interface is up (Physical link is Up) and the unit is enabled (Unit 0 is enabled), but there is no neighbor discovery or ARP entry. Without a valid next-hop or neighbor reachability, ICMP echo requests cannot be forwarded, resulting in ping failure.

Exam trap

The trap here is that candidates often assume a ping failure is due to an interface being down or a firewall filter, but the exhibit clearly shows the interface is up and enabled, so the issue must be at the network layer with neighbor unreachability.

How to eliminate wrong answers

Option A is wrong because there is no evidence of a firewall filter blocking ICMP traffic; the output does not show any applied filter or statistics indicating dropped packets. Option B is wrong because the interface is not disabled at the unit level; the output explicitly states 'Unit 0 is enabled' and shows an IP address configured. Option D is wrong because the interface is not administratively down; the output shows 'Physical link is Up' and 'Interface is up', indicating no administrative shutdown.

37
MCQeasy

A network engineer is configuring a new Juniper MX router to replace an existing core router. The engineer has applied several configuration changes and wants to ensure that the new configuration can be tested safely. If the test fails (e.g., loss of management connectivity), the router should automatically revert to the previous configuration after a 5-minute period. The engineer performs a commit confirmed with a timeout of 5 minutes. After 4 minutes, the engineer verifies that the change is successful and wants to make it permanent. Which action should the engineer take to ensure the configuration persists?

A.Issue the 'rollback 0' command, then commit.
B.Issue the 'commit confirmed 5' command again to reset the timer.
C.Issue the 'request system reboot' command to reload the router.
D.Issue a standard 'commit' command to confirm the configuration.
AnswerD

Issuing a standard 'commit' command immediately activates the candidate configuration as the new permanent configuration in the active/committed hierarchy. This action also cancels the pending commit confirmed timer, preventing any automatic rollback to the previous configuration. It is the only proper step to finalize a configuration that was staged with 'commit confirmed'.

Why this answer

The correct action is D: issue a standard 'commit' command to confirm the configuration. In Junos, 'commit confirmed' activates the candidate configuration on a trial basis and automatically rolls back to the previous configuration unless it is confirmed within the specified timeout; issuing a normal 'commit' within that window makes the change permanent and cancels the rollback timer. Option A is wrong because 'rollback 0' loads the currently active configuration (the trial config) but does not by itself confirm it, and it is not the standard confirmation step.

Option B is wrong because re-issuing 'commit confirmed 5' merely restarts the confirmation timer rather than making the configuration persistent. Option C is wrong because rebooting the router would not confirm the candidate configuration and could even trigger the pending rollback behavior.

38
MCQhard

You are administering a Juniper MX240 router that provides connectivity to multiple customer sites. The router uses BGP to exchange routes with two upstream ISPs. Recently, you applied a new firewall filter to the loopback interface to restrict management access. After committing the configuration, you can no longer establish SSH sessions to the router from the management network. You are currently connected via console. The loopback filter is still applied. You suspect the filter is blocking SSH traffic from the management network. What should you do to restore SSH access without losing the other filter rules?

A.Roll back to the previous configuration using 'rollback 0' and commit.
B.Add a new term at the end of the filter that accepts SSH traffic from any source.
C.Add a new term at the beginning of the filter that accepts SSH traffic from the management network, then reorder the terms so that this term is evaluated first.
D.Delete the firewall filter from the loopback interface and commit.
AnswerC

Inserting a new accept term at the top of the filter and committing it ensures that SSH packets sourced from the management network match this term first, before any deny term can be evaluated. Junos first-match semantics guarantee that once the accept action is applied, no later term can override it. Limiting the source to the management network preserves the security boundary and only restores the intended SSH access, rather than allowing SSH from arbitrary sources.

Why this answer

Firewall filters in Junos are evaluated in order, and adding a term at the beginning that explicitly accepts SSH traffic from the management network ensures that the SSH packets are permitted before any subsequent deny terms are evaluated. This preserves all existing filter rules while restoring SSH access. The 'insert' command or reordering terms is necessary to place the new term first, as the default behavior appends new terms to the end of the filter.

Exam trap

The trap here is that candidates assume adding a permit rule anywhere in the filter will work, but they forget that Junos filters are order-dependent and that new terms are appended to the end by default, which may be after a deny term that blocks the traffic.

How to eliminate wrong answers

Option A is wrong because 'rollback 0' rolls back to the most recently committed configuration, which would remove the entire firewall filter and any other recent changes, not just the problematic rule. Option B is wrong because adding a term at the end of the filter that accepts SSH from any source would still be evaluated after any existing deny terms that might block SSH traffic, so it would not restore access. Option D is wrong because deleting the entire firewall filter from the loopback interface removes all security restrictions, not just the one blocking SSH, which violates the requirement to keep other filter rules.

39
MCQhard

A technician needs to upgrade the Junos OS on a device that is part of a redundant cluster. Which approach minimizes traffic disruption?

A.Use 'request system software add' on both nodes at the same time.
B.Upgrade both nodes simultaneously to reduce maintenance time.
C.Upgrade one node at a time, ensuring the cluster remains redundant.
D.Use the 'commit synchronize' command to keep configurations in sync after upgrade.
AnswerC

The correct method is to upgrade one node at a time: add the software to the backup node, let it reboot and rejoin the cluster as the new primary, then fail over and upgrade the old primary. This ensures that at least one node stays active throughout the process, preserving traffic forwarding and maintaining cluster redundancy. You can verify the cluster status with 'show chassis cluster status' before and after each node's reboot.

Why this answer

Upgrading one node at a time in a redundant cluster ensures that at least one node remains active to handle traffic while the other is being upgraded. This approach maintains cluster redundancy and minimizes traffic disruption, as the active node continues forwarding traffic using the gratuitous ARP or VRRP mechanisms, and the upgraded node rejoins the cluster after reboot.

Exam trap

The trap here is that candidates might think simultaneous upgrades are efficient or that 'commit synchronize' is related to software upgrades, but Junos requires sequential node upgrades in a cluster to maintain redundancy and avoid traffic loss.

How to eliminate wrong answers

Option A is wrong because using 'request system software add' on both nodes simultaneously would cause both nodes to reboot at the same time, resulting in a complete traffic outage for the cluster. Option B is wrong because upgrading both nodes simultaneously reduces maintenance time but causes a total loss of redundancy and traffic disruption, which is not acceptable for minimizing disruption. Option D is wrong because 'commit synchronize' is used to synchronize configuration changes between nodes, not to manage software upgrades; it does not address the upgrade process or traffic disruption.

40
MCQeasy

What is the purpose of the 'commit confirmed' command in Junos OS?

A.It compares the candidate configuration with the active configuration
B.It allows the administrator to test a configuration change with automatic rollback if confirmation is not received
C.It permanently saves the candidate configuration to the startup configuration
D.It confirms that a previous commit was successful
AnswerB

This is the correct purpose of 'commit confirmed' in Junos. When you issue 'commit confirmed', the candidate configuration is applied and a timer (default 10 minutes, configurable with 'confirm <minutes>') starts. If you do not explicitly confirm the commit with a subsequent 'commit confirm' before the timer expires, the device automatically reverts to the previous active configuration. This is essential for safely applying remote changes that might disrupt connectivity, because a lost connection means you cannot confirm, so the router rolls back automatically.

Why this answer

The 'commit confirmed' command in Junos OS applies a candidate configuration change and starts a confirmation timer (default 10 minutes). If the administrator does not issue a 'commit' command before the timer expires, the system automatically rolls back to the previous active configuration. This allows safe testing of changes, especially over remote connections, preventing lockout if the change breaks connectivity.

Exam trap

The trap here is that candidates confuse 'commit confirmed' with a simple confirmation prompt or a verification step, when in fact it is a timed rollback mechanism designed to prevent lockout during remote configuration changes.

How to eliminate wrong answers

Option A is wrong because comparing the candidate configuration with the active configuration is done using the 'show | compare' command or 'show configuration | compare', not 'commit confirmed'. Option C is wrong because permanently saving the candidate configuration to the startup configuration is achieved with 'commit' (or 'commit and-quit'), not 'commit confirmed'; the 'commit confirmed' command applies the change temporarily and requires a subsequent 'commit' to make it permanent. Option D is wrong because confirming a previous commit was successful is not a function of 'commit confirmed'; the system logs commit success or failure in the event log, and 'show system commit' displays the commit history, but 'commit confirmed' is used to test a change with automatic rollback, not to verify a past commit.

41
MCQmedium

Refer to the exhibit. An operator tries to ping 192.168.1.2 from this router and fails. The router can ping itself (192.168.1.1). What is the most likely cause?

A.Reverse path forwarding (RPF) check is dropping the echo request.
B.The remote host is not reachable or is not responding to ARP requests.
C.The interface is administratively down.
D.Proxy ARP is not configured on the interface.
AnswerB

To ping 192.168.1.2 from a directly connected interface, the router must first resolve that destination IP to a MAC address using an ARP request. If the remote host is down, unreachable at Layer 2, or configured with a different IP, it will not send an ARP reply, and the router will report the ping as failing (e.g., 'Host is down' or an incomplete ARP entry). Since the interface is up and has an IP in the same subnet, ARP resolution failure is the classic and most likely explanation for this symptom.

Why this answer

The router can ping its own interface (192.168.1.1), confirming that the interface is up and IP is configured correctly. The failure to ping 192.168.1.2 indicates that the router cannot reach the remote host, most likely because the host is down, not connected, or not responding to ARP requests. ARP resolution is required for the router to map the destination IP to a MAC address on the local subnet; without a successful ARP reply, the router cannot send the echo request.

Exam trap

The trap here is that candidates may confuse a local connectivity issue (like a down interface or RPF) with a remote host unreachability, but the ability to ping the local interface proves the interface is operational and the problem lies with the destination host or its ARP response.

How to eliminate wrong answers

Option A is wrong because reverse path forwarding (RPF) checks are used in multicast or unicast RPF (uRPF) scenarios to verify the source address of incoming packets, not to drop locally generated echo requests. Option C is wrong because if the interface were administratively down, the router would not be able to ping its own address (192.168.1.1). Option D is wrong because Proxy ARP is used to allow a router to respond to ARP requests on behalf of hosts on another subnet; it is not required for a router to ping a host on the same directly connected subnet.

42
MCQeasy

Refer to the exhibit. Which filesystem should the administrator investigate to free up disk space?

A./config
B./ (root)
C./dev
D./var
AnswerD

/var is the correct answer because it is a disk-backed partition that contains high-write operational data including system logs, temporary files, and core dumps, which accumulate over time. At 97% utilization, it is almost full and poses an imminent risk: if it fills, logging and certain system services may fail, and the device may become unstable. This near-capacity state makes /var the filesystem that should immediately concern an administrator.

Why this answer

The /var filesystem on Junos devices stores system logs, core dumps, and temporary files. When disk space is low, /var is the most common culprit because it contains rotating log files (e.g., messages, interactive-commands) and crash data that can accumulate rapidly. The administrator should investigate /var to free up space by clearing old logs or core files.

Exam trap

The trap here is that candidates often assume the root filesystem (/) is the primary space consumer, but Junos intentionally segregates dynamic data into /var, making it the correct target for disk space recovery.

How to eliminate wrong answers

Option A is wrong because /config is a dedicated partition for the active and backup configuration files (e.g., juniper.conf.gz), which are small and rarely cause disk space issues. Option B is wrong because / (root) contains the Junos kernel and base system files, which are static and do not grow significantly over time. Option C is wrong because /dev is a virtual filesystem for device nodes and does not consume persistent disk space.

43
MCQhard

What happens when a user issues the 'request system reboot' command without any options?

A.The device reboots after the current commit.
B.The device reboots immediately.
C.The device prompts for confirmation.
D.The device schedules a reboot in 5 minutes.
AnswerC

By default, 'request system reboot' is an interactive command that prompts for confirmation. When executed, it displays a message asking the user to confirm the action, and optionally warns about unsaved configuration changes. The user must respond affirmatively (typically 'yes' or 'y') before the device begins the reboot sequence. This confirmation step is a safety mechanism to prevent accidental reboots and is the default behavior unless the 'now' option is provided.

Why this answer

When a user issues the 'request system reboot' command without any options, Junos OS prompts for confirmation before proceeding. This is a safety mechanism to prevent accidental reboots, as the command does not automatically reboot the device immediately or schedule a delayed reboot by default.

Exam trap

The trap here is that candidates often assume 'request system reboot' behaves like a typical Linux 'reboot' command (immediate execution), but Junos requires explicit confirmation or the 'now' option to proceed without a prompt.

How to eliminate wrong answers

Option A is wrong because the 'request system reboot' command does not wait for a commit; it reboots the device immediately after confirmation, and the current configuration is already active. Option B is wrong because the command does not reboot immediately; it first prompts the user for confirmation to avoid unintended disruptions. Option D is wrong because the command does not schedule a reboot in 5 minutes; that behavior requires the 'at' or 'in' option (e.g., 'request system reboot at 12:00' or 'request system reboot in 5').

44
MCQeasy

You are a network administrator for a service provider that uses Juniper MX series routers to provide MPLS VPN services to customers. Management has requested that you implement a secure out-of-band management (OOBM) solution for all MX routers to ensure that management traffic is isolated from the production network, reducing the risk of unauthorized access and management plane attacks. You are tasked with designing the OOBM solution using a dedicated management interface (me0) and a separate management routing instance. Which of the following best practices should you follow?

A.Place me0 in the inet.0 routing table and rely on static routes
B.Enable VLAN tagging on me0 to separate management traffic into different subnets
C.Configure the me0 interface in the default routing instance with a simple ACL
D.Create a dedicated routing instance for management, assign me0 to it, and apply a firewall filter to restrict access
AnswerD

Creating a dedicated routing instance creates a separate RIB/FIB context for management, so me0's traffic never shares routes with production. Assigning me0 to that instance ensures incoming and outgoing management packets use only that isolated table. Applying a firewall filter on the interface or within the instance provides granular control over allowed sources/ports, while the routing-instance separation prevents transit use and route leakages. This combination is the recommended approach for out-of-band management isolation in Junos.

Why this answer

It follows Juniper's best practice for OOBM: creating a dedicated management routing instance (e.g., mgmt_junos) and assigning the me0 interface to it. This ensures management traffic is completely isolated from the production routing table (inet.0), preventing management plane attacks and unauthorized access. Applying a firewall filter on the me0 interface further restricts access to only authorized management hosts, aligning with security hardening guidelines.

Exam trap

The trap here is that candidates assume VLAN tagging (Option B) is a valid method for separating management traffic on any interface, but the me0 interface on Juniper MX routers does not support VLAN tagging as it is a dedicated Layer 3 out-of-band port, not a trunk port.

How to eliminate wrong answers

Option A is wrong because placing me0 in the inet.0 routing table mixes management traffic with production traffic, defeating the purpose of OOBM isolation and exposing the management plane to potential attacks. Option B is wrong because VLAN tagging on me0 is not supported; the me0 interface is a dedicated out-of-band management port that operates at Layer 3 and does not support subinterfaces or VLAN tagging. Option C is wrong because keeping me0 in the default routing instance (inet.0) does not isolate management traffic; a simple ACL is insufficient for full isolation, and the default instance is shared with production routes, violating OOBM principles.

45
MCQeasy

Which command shows the operational status of all interfaces in a brief format?

A.show interfaces terse
B.show interfaces statistics
C.show interfaces detail
D.show configuration interfaces
AnswerA

The 'show interfaces terse' command outputs a single-line entry per physical and logical interface, showing the administrative state (Admin) and operational state (Link) as up or down, along with the protocol family and configured IP addresses. This concise format is the go-to way to quickly assess the real-world status of all interfaces on a Junos device, making it the correct answer for this question.

Why this answer

The 'show interfaces terse' command displays a brief, one-line summary of each interface, including its administrative status (up/down), link status, protocol status, and configured IP addresses. This is the correct command for a concise overview of all interfaces' operational state, as specified in the Junos OS documentation.

Exam trap

The trap here is that candidates often confuse 'show interfaces terse' with 'show interfaces brief' (which does not exist in Junos) or assume 'show configuration interfaces' shows operational status, when it only shows configuration data.

How to eliminate wrong answers

Option B is wrong because 'show interfaces statistics' displays detailed packet and byte counters for each interface, not a brief operational status summary. Option C is wrong because 'show interfaces detail' provides extensive configuration and operational details for each interface, including hardware information and error counters, which is verbose rather than brief. Option D is wrong because 'show configuration interfaces' displays the configured interface settings from the candidate or active configuration, not the real-time operational status of the interfaces.

46
MCQeasy

An administrator is logged into a Juniper EX Series switch in configuration mode and wants to verify how the device will interpret a specific interface configuration before applying it. Which operational-mode command should the administrator use to validate the candidate configuration for syntax and semantic errors without committing it?

A.commit confirmed
B.show | compare
C.load override
D.commit check
AnswerD

The commit check command parses the candidate configuration and reports syntax or semantic errors without activating it, making it ideal for validation before committing. It runs the same checks as a commit but leaves the active configuration unchanged, so the administrator can safely verify interface syntax and references. This matches the scenario of validating a configuration on an EX Series switch before applying it.

Why this answer

The commit check command validates the candidate configuration for syntax and semantic errors without committing it, which is exactly what the administrator needs before applying interface changes. The other commands either apply changes or only show differences, so they do not provide a safe validation step. Using commit check ensures the configuration is correct before it becomes active.

Exam trap

The trap here is confusing commit check with commit confirmed, where the latter actually applies the configuration temporarily instead of only validating it.

47
MCQhard

A network engineer made several configuration changes on a Juniper QFX switch to implement new VLANs. After committing the changes, the engineer realized that the new configuration caused a critical loss of connectivity to the management network. The engineer needs to revert to the previous configuration that was working. The switch is still accessible via the console port, and the engineer has privilege level access. The previous configuration was committed two commits ago, and the current active configuration is the problematic one. Which action should the engineer take to restore the previous working configuration?

A.Use 'load override /config/juniper.conf.1.gz' followed by 'commit'.
B.Use 'delete system' to remove all configuration and then commit.
C.Execute 'rollback 0' followed by 'commit'.
D.Execute 'rollback 2' followed by 'commit'.
AnswerD

rollback 2 sets the candidate configuration to the snapshot saved two commit operations ago, stored as /config/juniper.conf.2.gz. This bypasses the two most recent commits, returning to the last known working configuration. A subsequent commit activates this as the new active configuration, effectively undoing the problematic changes.

Why this answer

The working configuration was committed two commits ago. The 'rollback 2' command loads the configuration from two commits prior into the candidate configuration. After that, 'commit' makes it active, restoring connectivity.

Note that 'rollback 1' would load the intermediate commit, which is also problematic, and 'rollback 0' refers to the current active configuration.

Exam trap

The trap here is confusing the rollback numbering: candidates often think 'rollback 0' reverts to a previous configuration, but it actually refers to the current active configuration, while 'rollback 1' is needed to go back one commit (the previous working state).

How to eliminate wrong answers

Option A is wrong because '/config/juniper.conf.1.gz' is the backup of the configuration that was active one commit ago, but using 'load override' loads that file into the candidate configuration without automatically applying it; however, the correct rollback command is simpler and more appropriate, and 'juniper.conf.1.gz' corresponds to the configuration before the last commit, not two commits ago. Option B is wrong because 'delete system' removes all system configuration, which would cause a complete loss of management access and is an irreversible destructive action, not a targeted rollback. Option C is wrong because 'rollback 0' reverts to the current active configuration (the problematic one), which does nothing to restore the previous working configuration.

48
MCQmedium

A Junos device has multiple configuration files saved. Which command shows the available rollback configurations?

A.show system configuration
B.show system rollback
C.show configuration | display rollback
D.show system commit
AnswerD

'show system commit' is the correct operational-mode command because it lists every committed configuration on the device, along with its commit ID, timestamp, user, and optional comment. These commit IDs are the exact rollback identifiers used to restore or inspect previous configurations with 'rollback <id>' or 'show system rollback <id>'. Thus it provides the complete inventory of rollback points needed to answer the question.

Why this answer

The 'show system commit' command displays a list of all committed configuration revisions, including their commit IDs and timestamps, which are used to roll back to a previous configuration. The rollback feature in Junos relies on these stored commit files, and the command explicitly shows the available rollback points.

Exam trap

The trap here is that candidates familiar with Cisco IOS might expect a 'show rollback' command to list available rollbacks, but Junos uses 'show system commit' for this purpose, and 'show system rollback' only shows the content of a specific rollback when given an ID.

How to eliminate wrong answers

Option A is wrong because 'show system configuration' is not a valid Junos command; the correct command to view the current active configuration is 'show configuration'. Option B is wrong because 'show system rollback' is not a valid command; the correct command to view a specific rollback configuration is 'show system rollback <id>', but it does not list available rollback configurations. Option C is wrong because 'show configuration | display rollback' is not a valid syntax; the correct way to view a specific rollback configuration is 'show configuration rollback <id>', and the 'display rollback' option is used with 'show system commit' to show the configuration differences, not to list available rollbacks.

49
MCQhard

A Juniper device fails to boot and stops at the 'loader>' prompt. What is the most likely cause of this issue?

A.Bad boot device or missing kernel
B.Corrupted configuration file
C.Hardware failure of the power supply
D.Missing root password
AnswerA

The loader prompt (typically 'loader>') is the bootloader's interactive menu, reached when it cannot locate a valid kernel to load. If the boot device is absent, unreadable, or the kernel file is missing/corrupt, the bootloader cannot proceed with the normal boot sequence and instead drops to this prompt for manual intervention. This is the expected symptom when storage or kernel integrity is compromised.

Why this answer

When a Juniper device stops at the 'loader>' prompt, it indicates that the boot process has failed to locate or load the kernel (juniper-kernel) from the boot device (e.g., internal flash, USB, or hard disk). This is typically caused by a corrupted boot device, missing kernel image, or incorrect boot device selection in the boot loader (UBoot or CFE). The loader prompt is a low-level environment used for recovery, not a sign of configuration or authentication issues.

Exam trap

The trap here is that candidates confuse a boot loader failure (loader prompt) with a configuration or authentication issue, assuming that any boot problem is due to a corrupted config or password, when in fact the loader prompt specifically indicates a missing or inaccessible kernel.

How to eliminate wrong answers

Option B is wrong because a corrupted configuration file would cause the device to boot but fail to load the configuration, resulting in the 'amnesiac' state or a request to enter recovery mode, not a stop at the 'loader>' prompt. Option C is wrong because a power supply failure would prevent the device from powering on at all, not allow it to reach the boot loader stage. Option D is wrong because a missing root password does not affect the boot process; it only prevents login after the system has fully booted, and recovery can be performed via the console or root password recovery procedure.

50
MCQmedium

A network engineer is configuring a new Juniper device and needs to ensure that the configuration is saved persistently across reboots. Which command should be used?

A.save
B.request system reboot
C.show configuration
D.commit
AnswerD

The `commit` command is the only way to make candidate configuration changes active and permanent in Junos. It runs full configuration validation and, if successful, installs the candidate into the active configuration store, which is what loads at reboot. Because `commit` persists the changes to storage and activates them at once, it is the required final step after editing any configuration.

Why this answer

The `commit` command activates the candidate configuration and saves it to the active configuration database, ensuring it persists across reboots. Without a commit, any changes made in candidate mode are lost when the device restarts.

Exam trap

The trap here is that candidates familiar with Cisco IOS may mistakenly think `save` or `write memory` is the equivalent command, but Junos requires an explicit `commit` to persist changes.

How to eliminate wrong answers

Option A is wrong because `save` is not a valid Junos CLI command; the correct command to write configuration to a file is `save configuration <filename>`, but it does not activate or persist the configuration across reboots. Option B is wrong because `request system reboot` triggers a system restart but does not save any uncommitted configuration changes; any unsaved candidate configuration would be discarded. Option C is wrong because `show configuration` only displays the current active configuration; it does not save or persist any changes.

51
MCQmedium

You are a network administrator for a large enterprise. You have a Juniper SRX firewall that is used as the primary internet gateway. Users are reporting that they are unable to access certain external websites. You check the device and find that the security policies appear correct, and the routing is in place. You suspect that the issue might be related to the DNS resolution. You want to verify that the device can resolve DNS names and that the DNS server configuration is correct. Which command should you use to test DNS resolution from the Juniper device?

A.show system connections
B.ping <external website FQDN>
C.traceroute <external website FQDN>
D.show dns name-server
AnswerB

When you execute 'ping <external website FQDN>' on Junos, the CLI first resolves the hostname to an IP address using the DNS servers configured under 'system name-server'. A successful resolution is shown directly in the output, where ping reports the target IP before sending ICMP requests. If the DNS query times out or fails, Junos returns a 'unable to resolve hostname' error, making this an effective, one-command DNS resolution test. Note that even if ICMP is blocked by the remote host, the appearance of the IP address in the output already confirms forward DNS works.

Why this answer

The `ping` command with a fully qualified domain name (FQDN) forces the Juniper device to perform a DNS resolution before sending ICMP echo requests. If the device cannot resolve the FQDN, the ping will fail with a 'hostname not found' error, directly indicating a DNS configuration or reachability issue. This tests both the DNS server configuration and the device's ability to resolve names, which is essential for verifying DNS functionality.

Exam trap

The trap here is that candidates often confuse `show dns name-server` with a valid operational command, but Junos uses `show configuration system name-server` to view DNS server settings, and the `ping` command with an FQDN is the standard method to test live DNS resolution from the device.

How to eliminate wrong answers

Option A is wrong because `show system connections` displays active TCP/UDP connections and their states, not DNS resolution capabilities or configuration. Option C is wrong because `traceroute` with an FQDN also triggers DNS resolution, but it is designed to trace the path to the destination and is less direct for simply testing DNS resolution; a failed traceroute could be due to routing or firewall issues rather than DNS. Option D is wrong because `show dns name-server` is not a valid Junos command; the correct command to view DNS server configuration is `show configuration system name-server`.

52
MCQeasy

What is the default behavior when a user logs in to a Junos device and enters configuration mode?

A.The user must first commit before making changes.
B.The user can edit the candidate configuration.
C.The user can only view the configuration.
D.The user directly modifies the active configuration.
AnswerB

This is correct. By default, Junos separates the active configuration (the one currently used by the routing engine) from the candidate configuration. When a user logs in and enters configuration mode, they edit the candidate configuration with commands like 'set', 'edit', or 'delete'. These changes remain in the candidate until the user issues 'commit', at which point the candidate becomes the active configuration.

Why this answer

When a user enters configuration mode on a Junos device, they are placed into a private copy of the candidate configuration. This allows the user to make changes without affecting the active configuration until a commit operation is performed. Option B correctly describes this default behavior.

Exam trap

The trap here is that candidates familiar with Cisco IOS may assume changes are applied immediately (like in 'configure terminal'), but Junos requires an explicit commit to activate changes, and the candidate configuration is a separate, editable copy.

How to eliminate wrong answers

Option A is wrong because the user does not need to commit before making changes; they can edit the candidate configuration freely, and only a commit activates those changes. Option C is wrong because the user can edit the configuration in configuration mode, not just view it; viewing is the default in operational mode. Option D is wrong because Junos uses a separate candidate configuration; changes are not directly applied to the active configuration until explicitly committed.

53
MCQmedium

Your data center uses Juniper QFX5110 switches as leaf nodes in a Virtual Chassis Fabric (VCF) topology with QFX5100 as spine nodes. You are adding a new QFX5110 leaf node to the fabric. The new switch is physically connected to all spine nodes as per the cabling guidelines. However, after powering on the new switch, it does not automatically join the fabric. The existing fabric shows the new switch's member ID as 8, but it remains in 'standalone' state. The VCF has been operational for several months without issues. You check the configuration on the existing VC and notice that the 'virtual-chassis' configuration does not include the new member. What is the most likely reason the new switch does not join?

A.The new switch is running a different version of Junos that is not compatible with the fabric
B.The new switch does not have the same virtual-chassis ID configured as the existing fabric
C.The new switch is only connected to one spine node, and VCF requires full mesh connections to all spines
D.The new switch has 'set virtual-chassis no-split-detection' enabled, preventing it from joining
AnswerB

In a Juniper Virtual Chassis Fabric, every member must share the same virtual-chassis ID (VC-ID) to be recognized as part of the fabric. If the new leaf's VC-ID differs, it will not accept member-add requests and will remain isolated even though physically connected. The VC-ID is typically configured at initial provisioning, and mismatches manifest as the device failing to join the fabric.

Why this answer

In a Virtual Chassis Fabric (VCF), all member switches must share the same virtual-chassis ID to be recognized as part of the same fabric. The existing fabric has a configured virtual-chassis ID, but the new QFX5110, by default, has a different or no virtual-chassis ID set. Without a matching virtual-chassis ID, the new switch cannot join the fabric and remains in 'standalone' state, even though it is physically connected and assigned a member ID.

Exam trap

The trap here is that candidates may assume a switch with a member ID assigned has successfully joined the fabric, but in VCF, member ID assignment happens early in the discovery process and does not guarantee full integration—the switch must also have a matching virtual-chassis ID to move out of 'standalone' state.

How to eliminate wrong answers

Option A is wrong because Junos supports mixed software versions in a VCF only if they are within the same major release train and compatible; the question states the fabric has been operational for months, and version incompatibility would typically cause a different error (e.g., 'version mismatch') rather than a 'standalone' state with a member ID assigned. Option C is wrong because VCF does not require full mesh connections to all spines; the cabling guidelines for VCF typically require each leaf to be connected to at least two spines for redundancy, but a single connection would not prevent the switch from joining—it would still join and then potentially have forwarding issues. Option D is wrong because 'set virtual-chassis no-split-detection' is a feature used to disable split-brain detection in a Virtual Chassis (not VCF) and is not relevant to a new switch joining a VCF; it does not prevent a switch from joining the fabric.

54
MCQmedium

Refer to the exhibit. An administrator wants to see authentication-related logs like SSH logins. In the current configuration, which log file contains this information?

A.utmp
B.interactive-commands
C.security
D.messages
AnswerD

The 'messages' file is the default syslog destination in Junos that captures a broad range of system events, including authentication and authorization messages. By default, the authentication facility is logged to /var/log/messages, so SSH login attempts (both successful and failed) appear there. This is confirmed by the 'show log messages' command, which reveals entries from sshd that contain 'Accepted password' or 'Failed password'.

Why this answer

In Junos, authentication-related logs such as SSH login attempts are recorded by default in the 'messages' log file. This file captures syslog messages for various system events, including authentication successes and failures. The 'interactive-commands' log file only logs user-executed CLI commands after successful login, not the authentication process itself.

The 'security' log is intended for firewall and security policy events, and 'utmp' is for user accounting. Therefore, option D is correct.

Exam trap

The trap is that candidates may assume interactive-commands logs authentication events because it records CLI commands, but authentication occurs before command logging begins. The default location for authentication logs is the messages file.

How to eliminate wrong answers

Option A is wrong because utmp is a Unix-style file that tracks currently logged-in users, not historical authentication logs; Junos does not use utmp for persistent logging of SSH logins. Option C is wrong because the 'security' log file is used for security-related events like firewall filters, NAT, and IPsec, not for authentication or SSH login logs. Option D is wrong because the 'messages' log file contains general system messages (e.g., kernel, interface, and daemon events) but does not specifically capture interactive command or authentication logs.

55
MCQmedium

A network operator needs to backup the current configuration to a file on the local flash. Which command accomplishes this?

A.request system configuration rescue save
B.save /var/tmp/backup.conf
C.commit and-quit
D.show configuration | save /var/tmp/backup.conf
AnswerD

The `show configuration | save /var/tmp/backup.conf` command is the correct operational-mode method to back up the active configuration. `show configuration` displays the current committed configuration from operational mode, and the pipe to `save` redirects that output to a file, creating an ASCII text backup. This is a common practice for configuration archiving, as it captures exactly what is running without entering configuration mode. It is the only option that produces a usable backup file of the current configuration.

Why this answer

The correct command to backup the current configuration from operational mode is `show configuration | save /var/tmp/backup.conf`. This pipes the active configuration to the save command, writing it to the specified file. Option B (`save /var/tmp/backup.conf`) is a configuration mode command and will not work in operational mode.

Option A saves the rescue configuration, not the active configuration. Option C commits the configuration and exits but does not save to a file.

Exam trap

Watch out for the assumption that `save` alone works in operational mode — it is only available in configuration mode. The operational mode equivalent requires piping `show configuration` to `save`.

How to eliminate wrong answers

Option A is wrong because `request system configuration rescue save` saves the current active configuration as the rescue configuration, not to an arbitrary file path like `/var/tmp/backup.conf`. Option C is wrong because `commit and-quit` commits the candidate configuration and exits configuration mode, but does not save a backup copy to a file. Option D is wrong because `show configuration | save /var/tmp/backup.conf` saves the output of `show configuration` (which displays the active configuration) to a file, but this is a pipe to `save` that writes the text output, not a direct configuration backup command; it works but is less standard and can include formatting artifacts, whereas `save` is the proper operational-mode command for this task.

56
MCQhard

Your enterprise network uses Juniper EX4300 switches in a collapsed core design with RSTP (802.1w) as the Layer 2 loop prevention protocol. You add a new EX2300 switch to an access closet and connect it to two different core switches using two uplink interfaces configured in an LACP LAG. After connecting the new switch, you notice intermittent connectivity issues across the entire network, with some devices reporting temporary packet loss. The issue occurs sporadically, especially during configuration changes or when links flap. You suspect the problem is related to RSTP. Upon investigation, you see that the new switch's uplink interfaces are both in the forwarding state, but occasionally one of them transitions to blocking and then back to forwarding. What is the most likely cause of the intermittent issues?

A.The LACP system priority is set too low on the new switch, causing it to lose LACP negotiations
B.The LAG is not recognized as a single logical link by RSTP, causing RSTP to see two separate links and create a loop
C.The uplink interfaces are configured as alternate ports instead of root ports
D.The new switch has a different root bridge priority, causing it to become the root and disrupting topology
AnswerB

RSTP should treat a LAG as one link, but if the LAG is not configured correctly (e.g., missing 'lacp' or 'aggregate' statements), RSTP can see separate links and cause a loop, leading to intermittent blocking.

Why this answer

B is correct because the two uplinks are connected to two different core switches. A standard LACP LAG requires both links to terminate on the same remote switch. Since they terminate on different switches, the LAG does not form and RSTP sees two separate physical links.

This creates a loop between the EX2300 and the core (via the core switches' interconnection), so RSTP blocks one link. When configuration changes or link flaps occur, RSTP recalculates and the blocked port can temporarily transition to forwarding, causing intermittent packet loss.

Exam trap

The trap here is thinking that a LAG across two different switches works like a single LAG. In Junos, a standard LACP LAG spans only a single remote switch (unless using MC-LAG or virtual chassis). Without that, RSTP treats the links as separate and blocks one.

How to eliminate wrong answers

Option A is wrong because LACP system priority affects which switch controls the LAG during negotiation, but it does not cause RSTP to see separate links; even with correct LACP negotiation, if the interfaces are not configured as a logical ae interface, RSTP still treats them as individual links. Option C is wrong because alternate ports are a normal RSTP role for backup paths and do not inherently cause intermittent issues; the problem is that RSTP is actively blocking one of the LAG member links to prevent a loop, not that the ports are in an alternate role. Option D is wrong because a different root bridge priority would cause a new root election, but the question states the new switch's uplinks are both in forwarding state initially, and the issue is specifically related to RSTP blocking one link due to loop detection, not a root bridge change.

57
MCQeasy

Which command is used to view the terminal history of commands entered by the user?

A.show system commit
B.show cli history
C.show configuration
D.show log messages
AnswerB

The `show cli history` command prints a numbered list of commands entered by the user during the current terminal session, including both operational and configuration mode commands. This is the correct tool for viewing the terminal history of commands. The history buffer is session-scoped, so it only reflects commands issued in the current login session, and the list can be used to quickly re-execute a prior command.

Why this answer

The 'show cli history' command displays the list of previously entered CLI commands in the current session, allowing users to recall and re-execute them. This is a Junos-specific command that provides a terminal history feature, distinct from the commit history or system logs.

Exam trap

The trap here is that candidates often confuse 'show system commit' (which shows configuration commit history) with 'show cli history' (which shows the terminal command history), as both involve 'history' but serve entirely different purposes.

How to eliminate wrong answers

Option A is wrong because 'show system commit' displays the commit history (list of configuration changes committed), not the terminal command history. Option C is wrong because 'show configuration' displays the current active configuration, not the CLI command history. Option D is wrong because 'show log messages' displays system log messages (syslog entries), not the user's command history.

58
Multi-Selecthard

Which THREE statements about the Junos OS file system are true? (Choose three.)

Select 3 answers
A.The /etc directory contains all log files
B.The /altroot directory is used for user-uploaded files
C.The active configuration is stored in the /config directory
D.Log files are typically stored in /var/log
E.The file system is UNIX-like with directories such as /, /var, /config
AnswersC, D, E

The active Junos configuration is stored as the file juniper.conf.gz in the /config directory, which is a separate partition mounted at boot. This location persists across reboots and is distinct from the running configuration held in /var/run, and from the candidate configuration edited with 'configure'. The /config directory also stores rescue configurations, which provide a known-good fallback if the active file becomes corrupted.

Why this answer

Option C is correct because the active Junos configuration is saved as juniper.conf.gz in the /config directory, which is a separate partition from the root file system. Option D is correct because Junos OS writes its log files, such as messages and interactive-commands, into the /var/log directory. Option E is correct because the Junos OS file system is a FreeBSD-based, UNIX-like hierarchy containing standard directories including /, /var, and /config.

Option A is incorrect because /etc holds system configuration files, not log files, which reside in /var/log. Option B is incorrect because /altroot is a backup root partition used for alternate boot images, not for user-uploaded files, which are typically placed in /var/tmp or /var/home.

Exam trap

The trap here is that candidates confuse the `/etc` directory (which stores system configs, not logs) with the standard Linux convention, or they mistakenly think `/altroot` is for user files instead of its actual purpose as a backup root filesystem.

59
Multi-Selectmedium

Which two statements correctly describe Junos OS login classes? (Choose two.)

Select 2 answers
A.They allow users to enter only operational mode.
B.They are defined under the [edit system login class] hierarchy.
C.They are automatically assigned to all users by default.
D.They can restrict access to configuration mode.
E.They cannot be modified after creation.
AnswersB, D

Login classes are indeed configured under the [edit system login class] hierarchy in the Junos OS configuration. This hierarchy allows an administrator to define named classes, such as 'super-user', 'read-only', or custom classes, and assign permissions to each. For example, the command 'set system login class myclass permissions view' creates a class under that hierarchy, confirming that this is the definitive location for defining login class attributes in Junos.

Why this answer

Option B is correct because login classes are configured at the [edit system login class class-name] hierarchy in Junos OS, where you define permissions and other login parameters. Option D is correct because a login class can include or exclude the configure permission, thereby restricting whether a user can enter configuration mode. Options A, C, and E are incorrect: login classes do not force operational-mode-only access (that depends on permissions such as configure), they are not automatically assigned to all users by default (each user must be associated with a class, otherwise the default class applies), and they can be modified or deleted after creation.

Exam trap

The trap here is that candidates often confuse login classes with user accounts, assuming classes are automatically applied or immutable, when in fact they are manually assigned and fully configurable.

Ready to test yourself?

Try a timed practice session using only Junos OS Fundamentals questions.